I feel compelled to point out that if your Untangle ever has to deal with those "certain kinds of malware", your box is already lost.
But yes, this is a huge deal for enterprise users. It doesn't change much for the current installation base. but it does provide a ton of toys for those of us making Untangle dance in advanced virtualization fabrics.
But for the SMB and Home users, this means Intel Gen8 and younger now might actually work. Debian is still a bit new at most of it, but at least that can be addressed with kernel modules. Up until v16, it just flat couldn't work because those platforms are EFI only.